[rb-general] blog post -- in-toto at rb-summit

Lukas Puehringer lukas.puehringer at nyu.edu
Wed Jan 23 16:14:43 CET 2019


Dear all,

We just published a blog post about the Paris summit on our lab website:
https://ssl.engineering.nyu.edu/blog/2019-01-18-in-toto-paris

It is both a recap of the event, and a high-level introduction to how we
use in-toto to communicate and verify rebuild attestations (in Debian).

And it is also an invitation to get involved. We'd appreciate any help
on the following items:
- Package our relevant software for Debian [1], [2], [3]
- Deploy independent rebuilders [4]
- Explore ways of integration for other distros/projects

If you're interested please reach out to me/us!

Best,
Lukas

ps: I also wanted to say that I had a really good time at the summit.
Thanks for all the hard work and for being a warm and welcoming community!


[1] https://github.com/in-toto/in-toto
[2] https://github.com/in-toto/apt-transport-in-toto
[3] https://github.com/secure-systems-lab/securesystemslib
[4] https://salsa.debian.org/reproducible-builds/debian-rebuilder-setup

-- 
lukas.puehringer at nyu.edu
PGP fingerprint: 8BA6 9B87 D43B E294 F23E  8120 89A2 AD3C 07D9 62E8

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 874 bytes
Desc: OpenPGP digital signature
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20190123/6f4c5761/attachment.sig>


More information about the rb-general mailing list